Port 646Label Distribution Protocol

Label Distribution Protocol (LDP) is a key control protocol used within MPLS (Multiprotocol Label Switching) networks, enabling efficient and scalable routing by assigning labels to data packets. It facilitates the dynamic distribution and management of labels between routers, simplifying packet forwarding decisions and improving overall network performance in large-scale, multi-service network infrastructures..

transport
tcp · udp

2 transports registered

in transit
cleartext

payload readable on path

assignment
official

registered with iana

risk
4/10

caution

lookups
9,010

rank 542 of 993 · top 55%

Technical Details

what runs on :646

Overview:

Label Distribution Protocol (LDP) operates as a signaling mechanism within MPLS architectures, facilitating the mapping of packet routes by distributing label bindings among adjacent routers. This allows MPLS routers to set up Label-Switched Paths (LSPs) dynamically without manual intervention.

How It Works:

LDP establishes control sessions over TCP (by default on port 646) between Label Switching Routers (LSRs). These routers exchange label mapping information, enabling each device to associate a network prefix with a locally assigned label. The label bindings disseminated via LDP help build a consistent forwarding table across the MPLS domain, ensuring that packets follow predetermined paths based on labels rather than IP lookups.

Protocol Features:

  • Supports both IPv4 and IPv6 label bindings
  • Operates in both downstream unsolicited and downstream on demand modes
  • Utilizes TCP for reliable transmission of control messages
  • Can operate over UDP for discovery of LDP peers
  • Integrates with existing routing protocols (e.g., OSPF, IS-IS) for scalable deployment

LDP simplifies the management of MPLS networks by automating label distribution and path setup, which is crucial for efficient traffic engineering and service differentiation.

Security Information

exposure of :646

risk score

4/ 10caution

worth attention. how exposed you are depends on configuration — don't leave it reachable from the internet without a reason.

network services averages 3.9 across 604 ports — this one sits 0.1 above.

in transit

cleartext

credentials and payloads are readable by anyone on path

assignment

official

registered with iana for this service — scanners fingerprint it by number

reachable over

tcp · udp

udp is connectionless — source addresses are trivially spoofed and it is a reflection favourite

security overview

Common Vulnerabilities:

  • Unauthorized Access: Without proper authentication, malicious entities can establish LDP sessions and inject incorrect label mappings, leading to traffic hijacking or disruption.
  • Denial of Service (DoS): Attackers can flood the LDP port with connection requests or malformed packets, overwhelming the control plane.
  • LDP Spoofing: Crafting spoofed LDP packets to confuse label bindings or hijack LSPs.

Common Mitigations:

  • Authentication: Employ LDP Hello message authentication (such as MD5) to ensure trusted peer communication.
  • Access Controls: Enforce strict ACLs and filtering to limit which devices can initiate LDP sessions.
  • Network Segmentation: Run MPLS control traffic on isolated or protected management VLANs.
  • Rate Limiting: Apply rate limiting on LDP sessions to mitigate DoS attempts.
  • Regular Auditing: Monitor LDP session logs and label mappings for anomalous activity.

Adopting these practices helps maintain the integrity and availability of MPLS label switching environments.

the 8 most looked-up other ports in network services — 604 ports carry that label.

risk mix of the 8 listed

  • caution100%

0 of 8 encrypted